Unknown attackers hijacked the official Microsoft account on X (formerly Twitter), which has more than 13 million followers, and used it on 1 October to promote what appeared to be a cryptocurrency pump-and-dump scheme. The attack began when the Microsoft account followed and reposted a tweet from an impersonating account (@clippymsftcto) centred on Microsoft's Clippy virtual assistant; while that account was suspended, a related account (@ClippyMSFT) was still promoting a $Clippy token claiming a liquidity pool paired directly with "$MSFT". Microsoft removed the attackers' posts and, through a spokesperson, confirmed unauthorised access, said the account had been secured and the unauthorised posts removed, and that the circumstances continue under investigation. In a now-deleted tweet the company apologised, said it does not support any cryptocurrency or crypto-related token, and said it would take legal action. Microsoft separately said no Clippy or Microsoft-branded token is authorised and that it will pursue legal action to remove the unauthorised token. It is not the first time a Microsoft X account has been compromised for crypto scams — the Microsoft India account was similarly hijacked in June 2024.
| Attribute | Detail |
|---|---|
| Sector | Retail & Entertainment & Sport |
| Date | 2026-10-03 |
| Source | BleepingComputer |
| Reliability | Tier 2 |